System Event ID 7034: Service crashed
- Event ID
- 7034
- Channel
- System
- Provider
- Service Control Manager
- Log file
- System.evtx
- Category
- Services
- Default logging
- Logged by default
What event 7034 means
Event 7034 is written when a service's process terminates without the service reporting a stop, and no recovery action is configured (with a recovery action, the SCM logs 7031 instead). param1 is the service display name and param2 the number of times it has happened.
Operationally it points to crashing services. In a security context it is one of the few traces left when an attacker kills a service process rather than stopping it cleanly: a clean stop produces 7036 stopped, a kill produces 7034 or 7031. Security agents, Sysmon and backup services are the usual targets.
Remote execution services can also end this way when their process exits abruptly, so a 7034 shortly after a 7045 for the same service fits a one-shot execution pattern.
When it is logged
Always logged to the System log.
Key fields
| Field | What it tells you |
|---|---|
| param1 | Display name of the service that terminated. |
| param2 | Number of times the service has terminated unexpectedly. |
Common benign sources
- Application services crashing due to bugs or resource exhaustion.
- Services killed by installers during upgrades.
What attackers do that produces it
- Killing EDR, antivirus, Sysmon or backup service processes to disable them.
- A malicious service installed for remote execution exiting abruptly after running its payload.
Investigation tips
- Check whether the service is security-related; if so, treat the kill as potential defense evasion.
- Look for Application 1000 or 1001 for the same process to distinguish a crash from a kill.
- Search 4688 or Sysmon 1 for
taskkill,sc, or unknown tools right before, and 7045 for new drivers.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighImportant Windows Service Terminated UnexpectedlyRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.